Storage Device Biometric Authentication and Data Line Deactivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing semiconductor memory devices, particularly non-volatile memory systems, are limited in their ability to operate independently of host devices that support self-encrypting drive (SED) technology, leading to dependency on specific host device capabilities.

Innovation Solution

A non-volatile memory system that includes a storage device connected to a host device via a physical cable with a power line and a data line, featuring a memory controller with a biometric module for authentication, a biometric processing circuit, a relink trigger circuit, and a data processing circuit capable of encrypting and decrypting data, allowing the system to temporarily deactivate the data line while power is supplied, enabling independent operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If storage devices support SED and operate in dependence on commands from a host device, then security protection is provided, but the storage device cannot operate independently when the host device does not support SED

Engineering Contradiction:
Improvesecurity protectionVSAvoidindependent operation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The storage device performs relinking operations autonomously without requiring host device commands. The controller detects connection status changes and automatically executes relinking to restore data access, enabling the device to serve itself and operate independently of host device capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The storage device proactively performs relinking operations when connection status changes are detected, before the host device can issue commands. This preliminary action ensures data accessibility is restored independently, without waiting for host device support or commands.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the data line is continuously active for data transmission, then data accessibility is maintained, but security vulnerabilities arise when the storage device should be in a secure state

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The data line's operational state is dynamically adjusted based on connection status. The data line is activated during normal data transmission and deactivated when connection changes occur, allowing the system to adapt its security posture dynamically without compromising normal data accessibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The data line is deactivated in advance when connection status changes are detected, preventing potential security vulnerabilities before they can occur. This preliminary protective action ensures that data transmission only occurs when the connection status is confirmed to be normal.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3832515B1Storage device including memory controller, and non-volatile memory system including the same and operating method thereof
Publication Date: 2025.03.05 SAMSUNG ELECTRONICS CO LTD
  • EP3832515B1 patent drawingFigure 1A
  • EP3832515B1 patent drawingFigure 1B
  • EP3832515B1 patent drawingFigure 1C

AI summary

A storage device is configured to be connected to a host device via a physical cable which includes a power line and a data line. The storage device includes a non-volatile memory, a data path controller configured to temporarily deactivate the data line while power is supplied from the host device via the power line, and a memory controller. The memory controller includes a biometric module configured to receive biometric data and perform user authentication based on the biometric data; a biometric processing circuit configured to change a state of the memory controller, based on a result of the user authentication; and a data processing circuit configured to encrypt and decrypt data. The data path controller is configured to temporarily deactivate the data line in response to the changed state of the memory controller.